LayerZero Attributes $290 Million Kelp Exploit to Security Misconfiguration, Links Attackers to North Korea

LayerZero has attributed the $290 million exploit of Kelp DAO to a security configuration issue, stating that the protocol's single-verifier setup, which was contrary to their recommendations, allowed the attack to occur. The attackers, believed to be associated with North Korea's Lazarus Group, compromised two RPC nodes that LayerZero's verifier relied on, and then launched a DDoS attack on other nodes to force a failover to the compromised ones. This allowed the attackers to fraudulently release 116,500 rsETH. LayerZero emphasizes that the attack was only possible due to Kelp's 1-of-1 verifier configuration and notes that its own protocol worked as designed, with the issue being a result of Kelp's security choices. The company will no longer support single-verifier setups and has confirmed that there was no contagion to other applications on the protocol.